Section: .. / 0611-advisories /
| /// File Name: |
lotusnotes_keyfiles.pdf |
Description:
|
FortConsult Security Advisory - It is possible to retrieve unencrypted data from the "names.nsf" database on Lotus Notes servers without being logged in.
| | Author: | Andrew Christensen | | Homepage: | http://www.fortconsult.net/ | | Related File: | 11.08.06-1.txt | | File Size: | 465791 | | Last Modified: | Nov 8 22:17:22 2006 |
| MD5 Checksum: | da0ec7b5b5e3e08dfef96944411396a9 |
|
| /// File Name: |
USN-375-1.txt |
Description:
|
Ubuntu Security Notice 375-1: \Stefan Esser discovered two buffer overflows in the htmlentities() and htmlspecialchars() functions. By supplying specially crafted input to PHP applications which process that input with these functions, a remote attacker could potentially exploit this to execute arbitrary code with the privileges of the application.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 38421 | | Last Modified: | Nov 3 17:29:11 2006 |
| MD5 Checksum: | a8e5654b52cccc7014be8d414e380b5a |
|
| /// File Name: |
sa22688.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for PHP. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22688/ | | File Size: | 36224 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 2cdca15bc491d9c63ce481a5fb13c78d |
|
| /// File Name: |
USN-380-1.txt |
Description:
|
Ubuntu Security Notice 380-1 - Steve Grubb discovered that netlink messages were not being checked for their sender identity. This could lead to local users manipulating the Avahi service.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 36145 | | Related CVE(s): | CVE-2006-5461 | | Last Modified: | Nov 14 00:36:04 2006 |
| MD5 Checksum: | 615a576f793040dda9e160492a32298c |
|
| /// File Name: |
USN-371-1.txt |
Description:
|
Ubuntu Security Notice 371-1: An error was found in Ruby's CGI library that did not correctly check for the end of multipart MIME requests. Using a crafted HTTP request, a remote user could cause a denial of service, where Ruby CGI applications would end up in a loop, monopolizing a CPU.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 35183 | | Last Modified: | Nov 2 19:24:37 2006 |
| MD5 Checksum: | db049394245c6abb33ab670b9606a8ac |
|
| /// File Name: |
sa22852.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for avahi. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/22852/ | | File Size: | 34534 | | Last Modified: | Nov 13 10:24:28 2006 |
| MD5 Checksum: | 94066708c6b0695e49eedf9ecb82fd4c |
|
| /// File Name: |
sa22881.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for php4 and php5. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22881/ | | File Size: | 34073 | | Last Modified: | Nov 15 22:19:38 2006 |
| MD5 Checksum: | 72d3836e55b9716238000e6c1cb5d328 |
|
| /// File Name: |
sa22624.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for ruby. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22624/ | | File Size: | 33922 | | Last Modified: | Nov 2 10:01:38 2006 |
| MD5 Checksum: | d35afd655212a7b22cba92b4b1e07470 |
|
| /// File Name: |
sa22713.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for php4. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22713/ | | File Size: | 30627 | | Last Modified: | Nov 8 18:29:38 2006 |
| MD5 Checksum: | 57490de4232be80c35f26d2fe9cac800 |
|
| /// File Name: |
USN-372-1.txt |
Description:
|
Ubuntu Security Notice 372-1: M. Joonas Pihlaja discovered that ImageMagick did not sufficiently verify the validity of PALM and DCM images. When processing a specially crafted image with an application that uses imagemagick, this could be exploited to execute arbitrary code with the application's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 20129 | | Last Modified: | Nov 2 19:24:27 2006 |
| MD5 Checksum: | d03135b6964ce1ae856b12e458c1ff0f |
|
| /// File Name: |
sa22730.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an updated for nvidia-glx. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges and potentially by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/22730/ | | File Size: | 19716 | | Last Modified: | Nov 6 13:07:49 2006 |
| MD5 Checksum: | 0727e7e053a2df9238cf2ee458ea55b5 |
|
| /// File Name: |
USN-377-1.txt |
Description:
|
Ubuntu Security Notice 377-1 - Derek Abdine discovered that the NVIDIA Xorg driver did not correctly verify the size of buffers used to render text glyphs. When displaying very long strings of text, the Xorg server would crash. If a user were tricked into viewing a specially crafted series of glyphs, this flaw could be exploited to run arbitrary code with root privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 19511 | | Related CVE(s): | CVE-2006-5379 | | Last Modified: | Nov 6 00:06:48 2006 |
| MD5 Checksum: | 3a8bfb6ecedfb6d10ccde1523c0092aa |
|
| /// File Name: |
sa22601.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for imagemagick. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22601/ | | File Size: | 19113 | | Last Modified: | Nov 2 10:01:38 2006 |
| MD5 Checksum: | b0c4c9133e0fafaf8439cce9a70711b7 |
|
| /// File Name: |
sa22817.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22817/ | | File Size: | 17353 | | Last Modified: | Nov 13 10:24:28 2006 |
| MD5 Checksum: | e079cd1a09a7f1c4a60b9a43d7c2a71f |
|
| /// File Name: |
dsa-1211-1.txt |
Description:
|
Debian Security Advisory 1211-1 - It was discovered that malformed TCP packets may lead to denial of service and possibly the execution of arbitrary code if the PowerDNS nameserver acts as a recursive nameserver.
| | Homepage: | http://www.debian.org/security | | File Size: | 16507 | | Related CVE(s): | CVE-2006-4251 | | Last Modified: | Nov 16 11:04:18 2006 |
| MD5 Checksum: | 7951d6e360d53e1b5ddfa6467350f6c2 |
|
| /// File Name: |
sa22903.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for pdns. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22903/ | | File Size: | 15634 | | Last Modified: | Nov 15 22:19:38 2006 |
| MD5 Checksum: | eb7cdd41180c08aa2e4a03ad0c511de8 |
|
| /// File Name: |
MDKSA-2006-194.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-194: A vulnerability in PostgreSQL 8.1.x allowed remote authenticated users to cause a Denial of Service (daemon crash) via certain aggregate functions in an UPDATE statement which were not handled correctly
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 15532 | | Last Modified: | Nov 1 17:19:31 2006 |
| MD5 Checksum: | 0f85e201fdaae2ce584087dacf4b0d3f |
|
| /// File Name: |
sa22815.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22815/ | | File Size: | 14761 | | Last Modified: | Nov 13 10:24:28 2006 |
| MD5 Checksum: | 38fdffa9e23869d9ca0c62ba1f84f722 |
|
| /// File Name: |
sa22998.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for imagemagick. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22998/ | | File Size: | 14490 | | Last Modified: | Nov 20 11:05:00 2006 |
| MD5 Checksum: | df1317d5753ac564baf8fc1ff4685ab1 |
|
| /// File Name: |
cisco-sa-20061108-csd.txt |
Description:
|
Cisco Security Advisory - Cisco Secure Desktop (CSD) software is affected by three vulnerabilities that may cause information produced and accessed during an Internet browsing session to be left behind on a computer after an SSL VPN session terminates, may allow users to evade the system policy that prevents them from leaving the Secure Desktop while a VPN connection is active, and may allow local users to elevate their privileges. The vulnerabilities described in this document exist in versions 3.1.1.33 and earlier of Cisco Secure Desktop.
| | Homepage: | http://www.cisco.com/warp/public/707/cisco-sa-20061108-csd.shtml | | File Size: | 14112 | | Last Modified: | Nov 8 22:21:32 2006 |
| MD5 Checksum: | 583f9dbdbc464da6aa70188db45f1b63 |
|
| /// File Name: |
dsa-1218-1.txt |
Description:
|
Debian Security Advisory 1218-1 - It was discovered that the proftpd FTP daemon performs insufficient validation of FTP command buffer size limits, which may lead to denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 13270 | | Related CVE(s): | CVE-2006-5815 | | Last Modified: | Nov 21 21:32:27 2006 |
| MD5 Checksum: | c3381ad5319b7494c53a33d43df063b4 |
|
|
|
|
|